2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1754 | MEDIUM | 4.7 | 0.5% | Apr 15, 2024 | The NPS computy WordPress plugin through 2.7.5 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-1746 | MEDIUM | 5.4 | 0.4% | Apr 15, 2024 | The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-1712 | MEDIUM | 4.7 | 0.5% | Apr 15, 2024 | The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-1660 | MEDIUM | 4.8 | 0.4% | Apr 15, 2024 | The Top Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-1310 | MEDIUM | 4.9 | 0.7% | Apr 15, 2024 | The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking produ... |
| CVE-2024-1307 | MEDIUM | 6.5 | 0.5% | Apr 15, 2024 | The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow us... |
| CVE-2024-1306 | MEDIUM | 5.4 | 0.2% | Apr 15, 2024 | The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to... |
| CVE-2024-1204 | MEDIUM | 4.3 | 0.5% | Apr 15, 2024 | The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitr... |
| CVE-2024-0902 | MEDIUM | 4.8 | 0.4% | Apr 15, 2024 | The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could... |
| CVE-2024-3776 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated re... |
| CVE-2024-3774 | MEDIUM | 5.3 | 0.4% | Apr 15, 2024 | aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restriction... |
| CVE-2024-3763 | MEDIUM | 5.4 | 0.5% | Apr 14, 2024 | A vulnerability was found in Emlog Pro 2.2.10. It has been rated as problematic. This issue affects some unknown process... |
| CVE-2024-3762 | MEDIUM | 5.4 | 0.5% | Apr 14, 2024 | A vulnerability was found in Emlog Pro 2.2.10. It has been declared as problematic. This vulnerability affects unknown c... |
| CVE-2024-3735 | MEDIUM | 6.3 | 0.6% | Apr 13, 2024 | A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic. Affected is an unknown ... |
| CVE-2024-3721 | MEDIUM | 6.3 | 86.5% | Apr 13, 2024 | A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects som... |
| CVE-2024-3720 | MEDIUM | 6.3 | 0.5% | Apr 13, 2024 | A vulnerability has been found in Tianwell Fire Intelligent Command Platform 1.1.1.1 and classified as critical. This vu... |
| CVE-2024-26817 | MEDIUM | 5.5 | 0.8% | Apr 13, 2024 | In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid inte... |
| CVE-2024-3662 | MEDIUM | 4.3 | 0.5% | Apr 13, 2024 | The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capabil... |
| CVE-2024-2583 | MEDIUM | 5.4 | 0.4% | Apr 13, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortc... |
| CVE-2024-3027 | MEDIUM | 6.4 | 0.3% | Apr 13, 2024 | The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2024-1957 | MEDIUM | 5.4 | 0.4% | Apr 13, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-32028 | MEDIUM | 4.1 | 0.3% | Apr 12, 2024 | OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `... |
| CVE-2024-31462 | MEDIUM | 6.3 | 0.7% | Apr 12, 2024 | stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui... |
| CVE-2024-32000 | MEDIUM | 4.3 | 0.4% | Apr 12, 2024 | matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. matrix-appservice-irc before version 2.... |
| CVE-2024-22359 | MEDIUM | 6.1 | 0.4% | Apr 12, 2024 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now